skillguard-cli Alternatives
skillguard-cli is an open-source command-line tool designed to scan and analyze third-party AI agent-skill files, including SKILL.md manifests, hooks, and bundled scripts, for security vulnerabilities. Below are 27 llm eval & observability apps with similar functionality to skillguard-cli, matched by what each product actually does — not ranked or scored. Explore each to find the closest fit for your use case.
- skill-guardgithub.com
skill-guard is an open-source CLI tool designed for AI developers to validate, secure, detect conflicts, and test agent skills. It provides a quality gate for agent skills, ensuring robust and secure deployment throughout their lifecycle. The tool is suitable for teams building or maintaining AI agents and skills.
- skill-auditorpypi.org
skill-auditor is an open-source command-line tool that scans AI Agent skills for security issues before installation. It acts as an install gate, helping developers and maintainers ensure that only safe and validated skills are added to their AI agents. Ideal for those building or managing AI agent frameworks.
- skill-sentinelpypi.org
skill-sentinel is an open-source CLI tool that leverages multi-agent AI analysis to scan Agent Skill packages for potential security threats. It is designed for developers and security professionals working with AI agent ecosystems, providing automated threat detection and analysis.
- t2i-skillguardgithub.com
Security scanner for AI skill files (SKILL.md)
- skilltotalpypi.org
SkillTotal is a security analysis tool for AI components. It scans an AI component before it is trusted and reports supply-chain risk, dangerous capabilities, prompt-injection, and exfiltration surfaces, all derived from the component itself. Its analysis is deterministic and static, with no execution and no LLM involvement. A submission can be a public git URL from GitHub, GitLab, Bitbucket, or Hugging Face, or an npm:/pypi: package. The supported component types named on the site include MCP servers, agent skills or plugins, model repositories, and packages. The resulting report includes a risk score, all capabilities the component exposes, a behavioral trait fingerprint mapped to the Cloud Security Alliance agentic threat model, MAESTRO, and MITRE ATLAS, and findings anchored to file, line, and snippet evidence. Reports can be exported as JSON or SARIF. The service supports scanning multiple servers by pasting a configuration, and it can scan a skill or project from an uploaded ZIP file. It also states that nothing is stored, public reports are cached and shared, and scans on the site run on the provider’s servers without executing the submitted code. SkillTotal is free and requires no account. It is open source under the Apache-2.0 license, and it can also be run locally so that code never leaves the machine. The page names GitHub and PyPI, and mentions a command-line install path through pipx install skilltotal.
- aisona-skill-guardpypi.org
aisona-skill-guard is an open-source CLI tool that audits agent skills and packages before installation, performing deterministic security checks and providing clear exit codes. It is designed for developers working with AI agents to help secure their supply chain and prevent unsafe code from running on their machines.
- Security Skillai-dev-skills.com
Security Skill is an open-source CLI tool that integrates advanced security modules into AI coding assistants such as Cursor, Claude, and Copilot. It helps developers detect and fix vulnerabilities automatically in their codebases.
- AgentGuard CLIpypi.org
AgentGuard CLI is an open-source command-line tool designed to block unsafe AI agents during continuous integration deployments. It integrates with CI pipelines to enforce security checks and prevent risky agents from being released. Ideal for DevOps teams and AI developers focused on secure deployment practices.
- skilldexpypi.org
Skilldex is a command-line tool and Python package for interacting with a community registry of Claude Code skills, subagents, and MCP servers. It enables searching, installing, validating, and auditing these components. Licensed under MIT, it is targeted at developers working with AI coding tools and agent frameworks.
- skillstatpypi.org
skillstat is an open-source command-line tool for diagnosing, auditing, and optimizing the skill usage of AI agents. It provides analytics and reports to help developers understand and improve agent performance across various tools.
- skillfedpypi.org
skillfed is an open-source CLI tool that enables developers to discover and install vetted agent skills for Claude Code environments. It provides a no-clone installer that integrates with Claude Code and supports the Model Context Protocol (MCP), making it easy to add new skills via the command line. Designed for AI agent developers seeking streamlined skill management.
- skill-labgithub.com
Evaluate agent skills via static analysis, trigger testing, and trace analysis. Run `sklab` after installing to scan your skills.
- skillgen-aigithub.com
Analyze any codebase and auto-generate AI agent skill files for Claude Code, Cursor, and other AI tools
- agent-skill-scannergithub.com
agent-skill-scanner is an open-source CLI tool that scans agent skill files for security vulnerabilities, including prompt injection, capability escalation, and data exfiltration. It applies 22 security rules to help AI developers and security researchers identify and mitigate risks in LLM agent skills. The tool is MIT licensed and suitable for anyone building or auditing AI agent systems.
- skillhostpypi.org
skillhost is an open-source CLI tool that allows developers to install and manage agent skills directly from Git repositories using symlinks. It streamlines the process of integrating new skills into AI agents, making development and testing more efficient. Ideal for AI agent developers and open-source contributors.
- skillxraypypi.org
skillxray is a command-line tool for AI developers to scan agent skills for prompt injection, hidden Unicode, dangerous commands, and leaked secrets. It helps ensure the security and integrity of AI agent skills before deployment.
- agentguard-toolpypi.org
AI-native quality gate for agent-generated code — scan, audit, auto-fix, trend
- SkillScanskillscan.sh
SkillScan was a free, local, and private scanner designed to detect security issues in AI agent skill files. The tool operated without requiring a GPU, incurred no per-scan fees, and did not require users to send their files to a company, emphasizing privacy and local analysis. Its approach involved static analysis and the use of pattern rules or a lightweight classifier to identify potentially malicious behaviors or instructions within skill files. The scanner was developed as an open-source project, with its code remaining publicly available even after its retirement. SkillScan's methodology centered on identifying problematic patterns, but its creator found that such tools, including SkillScan itself, often missed a significant portion of novel attacks or over-blocked to compensate. The tool was benchmarked alongside other similar scanners, and results indicated that static or rule-based approaches detected only a fraction of sophisticated threats, particularly those involving intent or context that simple pattern matching could not discern. SkillScan's development and subsequent benchmarking were aimed at providing detection capabilities that users could fully control—local, private, and open-source—without reliance on external services or cloud-based models. However, the project's findings highlighted the limitations of static and rule-based detection in this domain, especially when compared to more advanced reasoning models. The scanner has since been retired, but its code remains accessible for reference.
- skillhub-aipypi.org
skillhub-ai is an open-source CLI package manager for AI agent skills, enabling developers to install, compose, and publish skills for various AI agents. It supports integration with platforms like Claude Code, Cursor, Codex, and Gemini, streamlining skill management for agent developers.
- SkillShieldskillshield.io
SkillShield is a web platform that analyzes AI agent skills and MCP servers for security vulnerabilities, providing a 0-100 trust score and embeddable badges. It helps developers and organizations ensure the safety of their AI integrations.
- skill-triviumgithub.com
A minimal CLI for managing AI agent skills
- skillwatchpypi.org
skillwatch is an open-source CLI tool that monitors external URLs used by AI agent skills and MCP tools, detecting bait-and-switch content changes, homoglyph attacks, and other supply chain security risks for AI systems.
- SkillFortifygithub.com
SkillFortify — Supply chain security scanner for AI agent skills. Supports 22 frameworks.
- cloneguardgithub.com
Raises the cost of prompt injection attacks against AI coding agents
- ai-agentguardgithub.com
ai-agentguard is an open-source CLI tool that monitors AI coding agents for security threats such as remote code execution, MCP poisoning, and API key theft. It is designed for developers working with AI agent frameworks to enhance security.
- contractguardianpypi.org
contractguardian is an open-source CLI tool that uses AI to scan contracts for red flags, unfair terms, and missing protections. It helps legal professionals and developers automate contract review and improve legal compliance.
- super-skill-clipypi.org
super-skill-cli is an open-source command-line tool for managing personal agent-skill packages. It provides a versioned registry, supports seed import, rollback, and explain commands, and is designed for developers working with agent-based automation workflows.